A question every business should be asking is: How quickly can we get back to business if something goes wrong?
Downtime is expensive, and in extreme cases, can even affect the wider economy — with the Jaguar Land Rover cyberattack estimated to have wiped out 0.1% of the UK’s GDP.
That’s why legislation such as the EU NIS2 Directive places a strong emphasis on recovery capability, not just prevention, for companies deemed “critical” or “important.” Even organizations that are not directly subject to NIS2 may still need to demonstrate appropriate safeguards if they want to do business with customers, partners or suppliers that are.
But every company should be asking this question, whether they are affected by the legislation or not. Backup is no longer simply about having another copy of your data. It’s a key part of any disaster response and how quickly you can move from recovery to normal business operations.
That’s why backup and recovery discussions are moving beyond IT departments and becoming board-level priorities.
How a good backup strategy supports NIS2
For many years, the widely accepted backup framework was:
- 3 cópias dos dados (para proteção contra perda de dados)
- 2 formatos diferentes (armazenados em pelo menos dois tipos de mídia)
- 1 cópia externa (para proteção contra desastres físicos)
No entanto, recomenda-se agora adotar mais duas medidas para garantir a verdadeira eficácia do backup:
- 1 cópia imutável (garantindo backups à prova de ransomware)
- Não tenho dúvidas de que você conseguirá recuperar os dados (testes regulares garantem a confiabilidade)
This evolving approach has a key part to play in NIS2 compliance.
What does NIS2 say about backup strategy?
At NIS2’s core is a focus on recovery and business continuity. It’s about ensuring disruption is kept to a minimum in the event of an incident. As such, most sections of NIS2 legislation are supported by a good backup strategy.
Three areas are particularly relevant.
One of the pillars of NIS2 is “policies to assess effectiveness.” Put simply, this isn’t just about the belief you have effective backup in place — it’s the ability to prove you do.
A backup is useless if you can’t use it. The “0 doubt you can recover” principle should form part of any recovery strategy, supported by documented recovery procedures and regular testing. Organizations need confidence that when recovery is required, it will work as expected.
Meanwhile, the immutable copy addresses the legislation’s need for “business continuity measures” and basic “computer hygiene.” It’s vital to have a copy of data that cannot be altered or deleted and can act as a known and reliable restore point if needed. This is necessary for general disaster recovery and offers a reliable version of data in the event of a cyberattack or ransomware incident.
Avoid cloud complacency
One of the biggest misconceptions in modern IT is the assumption that cloud services automatically provide complete protection, and that providers will handle backup and recovery. The problem is exacerbated by SaaS, where the promise of instant access to a solution is enticing and often achieved without IT involvement.
Even well-established services like Microsoft 365 can have backup blind spots if organizations do not have an independent protection strategy in place
The term “cloud blindness” has been coined for this and other areas of cloud complacency.
While cloud services may bake in a certain amount of resiliency, businesses cannot take a hands-off approach to critical areas such as backup and recovery.
Businesses need to employ a zero-trust policy when it comes to their data integrity. Regardless of who has stored the data or where, and regardless of the promises given in terms of reliability, the backup strategy must remain consistent across the board.
Backups are about getting back to business
In a world where ransomware attacks are increasingly common and SaaS outages are frequently making headlines, backups need to be a key part of any compliance posture.
Every moment of downtime is potentially lost revenue. The legislation’s approach to making IT part of boardroom governance is good for IT teams, and Datto has long been making the case for backups to be an important part of this discussion.
Read Datto’s The ultimate guide to BCDR: Why backup and disaster recovery matter




